CVE-2018-1158: Medium severity mikrotik routeros vulnerability
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a stack exhaustion vulnerability. An authenticated remote attacker can crash the HTTP server via recursive parsing of JSON.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1158?
CVE-2018-1158 is classified as a medium severity vulnerability due to its potential to cause service disruption.
How do I fix CVE-2018-1158?
To fix CVE-2018-1158, update your MikroTik RouterOS to version 6.40.10 or later, or version 6.42.8 or later.
Who is affected by CVE-2018-1158?
CVE-2018-1158 affects all MikroTik RouterOS versions before 6.40.10 and 6.42.8 that are vulnerable to this stack exhaustion issue.
What type of attack is associated with CVE-2018-1158?
CVE-2018-1158 is associated with an authenticated remote attack that exploits recursive parsing of JSON.
What are the potential consequences of CVE-2018-1158?
The potential consequences of CVE-2018-1158 include crashing the HTTP server, which can lead to denial of service.